2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-35394 | CRITICAL | 9.8 | 99.9% | Aug 16, 2021 | Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as... |
| CVE-2021-35393 | CRITICAL | 9.8 | 70.3% | Aug 16, 2021 | Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP... |
| CVE-2021-24527 | CRITICAL | 9.8 | 7.7% | Aug 16, 2021 | The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to rese... |
| CVE-2021-25955 | CRITICAL | 9 | 0.9% | Aug 15, 2021 | In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows l... |
| CVE-2021-37705 | CRITICAL | 10 | 2.4% | Aug 13, 2021 | OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incompl... |
| CVE-2021-21830 | CRITICAL | 9.8 | 2.3% | Aug 13, 2021 | A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ X... |
| CVE-2021-21829 | CRITICAL | 9.8 | 2.5% | Aug 13, 2021 | A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem funct... |
| CVE-2021-38302 | CRITICAL | 9.8 | 1.0% | Aug 13, 2021 | The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection. |
| CVE-2021-36789 | CRITICAL | 9.8 | 1.0% | Aug 13, 2021 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection. |
| CVE-2021-34823 | CRITICAL | 9.1 | 2.0% | Aug 13, 2021 | The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in... |
| CVE-2021-3352 | CRITICAL | 9.1 | 1.0% | Aug 13, 2021 | The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0... |
| CVE-2021-36380 | CRITICAL | 9.8 | 97.6% | Aug 13, 2021 | Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dns... |
| CVE-2021-32071 | CRITICAL | 9.8 | 1.2% | Aug 13, 2021 | The MiCollab Client service in Mitel MiCollab before 9.3 could allow an unauthenticated user to gain system access due t... |
| CVE-2021-1104 | CRITICAL | 9.8 | 1.7% | Aug 13, 2021 | The RISC-V Instruction Set Manual contains a documented ambiguity for the Machine Trap Vector Base Address (MTVEC) regis... |
| CVE-2021-38621 | CRITICAL | 9.1 | 1.0% | Aug 13, 2021 | The remove API in v1/controller/cloudStorage/alibabaCloud/remove/index.ts in netless Agora Flat Server before 2021-07-30... |
| CVE-2021-27741 | CRITICAL | 9.1 | 1.2% | Aug 13, 2021 | " Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection" |
| CVE-2021-37353 | CRITICAL | 9.8 | 2.9% | Aug 13, 2021 | Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php. |
| CVE-2021-37350 | CRITICAL | 9.8 | 79.3% | Aug 13, 2021 | Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper i... |
| CVE-2021-37346 | CRITICAL | 9.8 | 73.6% | Aug 13, 2021 | Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation ... |
| CVE-2021-37344 | CRITICAL | 9.8 | 96.8% | Aug 13, 2021 | Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of s... |
| CVE-2021-31698 | CRITICAL | 9.8 | 1.9% | Aug 12, 2021 | Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shel... |
| CVE-2021-31556 | CRITICAL | 9.8 | 1.6% | Aug 12, 2021 | An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not e... |
| CVE-2021-29377 | CRITICAL | 9.8 | 1.6% | Aug 12, 2021 | Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary cod... |
| CVE-2021-28890 | CRITICAL | 9.8 | 1.3% | Aug 12, 2021 | J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) ... |
| CVE-2021-28121 | CRITICAL | 9.8 | 1.7% | Aug 12, 2021 | Virtual Robots.txt before 1.10 does not block HTML tags in the robots.txt field. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now